pub mod squeezer;
pub use squeezer::FeatureSqueezer;
pub mod session_replay_guard;
pub use session_replay_guard::{ClientFingerprint, SessionReplayDetector, SessionStatus};
pub mod unbypassable_enforcer;
pub use unbypassable_enforcer::{MandatoryComplianceEnforcer, mandatory_compliance_middleware};
use axum::{
async_trait,
extract::FromRequestParts,
http::{request::Parts, StatusCode, header},
};
use ferrox_security::PasetoAuth;
use ferrox_errors::AppError;
pub struct RequireRole(pub String);
#[async_trait]
impl<S> FromRequestParts<S> for RequireRole
where
S: Send + Sync,
{
type Rejection = AppError;
async fn from_request_parts(parts: &mut Parts, _state: &S) -> Result<Self, Self::Rejection> {
let auth_header = parts.headers.get(header::AUTHORIZATION)
.and_then(|value| value.to_str().ok())
.ok_or_else(|| AppError::Unauthorized("Missing Authorization header".into()))?;
if !auth_header.starts_with("Bearer ") {
return Err(AppError::Unauthorized("Invalid token format".into()));
}
let token = &auth_header[7..];
let role = "admin";
Ok(RequireRole(role.to_string()))
}
}